imPC@ndo IT

Tracker / CVE-2021-44224

CVE-2021-44224

High 8.2

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

Affected products and versions

apache http_server · 2.4.7 → 2.4.52
apple mac_os_x
apple macos · … → 10.15.7
apple macos · 11.0 → 11.6.6
apple macos · 12.0.0 → 12.4
debian debian_linux
fedoraproject fedora
oracle communications_element_manager · … → 9.0
oracle communications_operations_monitor
oracle communications_session_report_manager · … → 9.0
oracle communications_session_route_manager · … → 9.0
oracle http_server
oracle instantis_enterprisetrack
tenable tenable.sc · 5.14.0 → 5.20.0
tenable tenable.sc · 5.16.0 → 202201.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References